CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72312

highCVSS 7.9covered by 1 sourcefirst seen 2026-08-15
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix VF bringup affecting PF promiscuous state Mbox handling of nix_set_rx_mode for a VF with promiscuous and all_multi flags set to false causes deletion of the PF's promiscuous and allmulti MCAM rules. This occurs because the APIs that enable/disable these rules operate only on the PF, even when the mbox request is made via a VF interface. Guard both rvu_npc_enable_allmulti_entry() and rvu_npc_enable_promisc_entry() disable paths with an is_vf() check so that a VF bringing up or tearing down its interface cannot inadvertently clear the PF's MCAM rules.

⚡ Watch CVE-2026-72312

Get an email if CVE-2026-72312 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-72312

CVE.org record

Embed the live status

CVE-2026-72312 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72312 status](https://www.csirts.com/badge/CVE-2026-72312)](https://www.csirts.com/cve/CVE-2026-72312)